βΌ CVE-2021-43282 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker within scanning range of the Wi-Fi network can thus scan for Wi-Fi networks to obtain the default key.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43295 βΌ
π Read
via "National Vulnerability Database".
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.π Read
via "National Vulnerability Database".
π΄ Whatβs the Difference Between SASE and SD-WAN? π΄
π Read
via "Dark Reading".
While SD-WAN is a key part of a hybrid workplace and multicloud operation, it should be treated as a stepping stone to SASE, not an alternative.π Read
via "Dark Reading".
Dark Reading
Whatβs the Difference Between SASE and SD-WAN?
While SD-WAN is a key part of a hybrid workplace and multicloud operation, it should be treated as a stepping stone to SASE, not an alternative.
π΄ HP Issues Firmware Updates for Printer Product Vulnerabilities π΄
π Read
via "Dark Reading".
More than 150 HP printer models have bugs that could enable attackers to steal data and gain an initial foothold on enterprise networks.π Read
via "Dark Reading".
Dark Reading
HP Issues Firmware Updates for Printer Product Vulnerabilities
More than 150 HP printer models have bugs that could enable attackers to steal data and gain an initial foothold on enterprise networks.
π΄ Legal Cases and Privacy Rulings Aim to Curtail Facial Biometrics π΄
π Read
via "Dark Reading".
Decisions in the UK and Australia, and lawsuits in the United States, could force facial-recognition providers to remove data from their machine-learning models.π Read
via "Dark Reading".
Dark Reading
Legal Cases and Privacy Rulings Aim to Curtail Facial Biometrics
Decisions in the UK and Australia, and lawsuits in the United States, could force facial-recognition providers to remove data from their machine-learning models.
βΌ CVE-2021-36330 βΌ
π Read
via "National Vulnerability Database".
Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to reuse old session artifacts to impersonate a legitimate user.π Read
via "National Vulnerability Database".
βΌ CVE-2021-41256 βΌ
π Read
via "National Vulnerability Database".
nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicious application installed on the same device can send it an arbitrary Intent that gets reflected back, unintentionally giving read and write access to non-exported Content Providers in Nextcloud News for Android. Users should upgrade to version 0.9.9.63 or higher as soon as possible.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36329 βΌ
π Read
via "National Vulnerability Database".
Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36326 βΌ
π Read
via "National Vulnerability Database".
Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit this vulnerability, leading to a downgrade in the communications between the client and server into an unencrypted format.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36327 βΌ
π Read
via "National Vulnerability Database".
Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to perform port scanning of internal networks and make HTTP requests to an arbitrary domain of the attacker's choice.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36328 βΌ
π Read
via "National Vulnerability Database".
Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database.π Read
via "National Vulnerability Database".
π¦Ώ Deloitte: How sensitive AI data may become more private and secure in 2022 π¦Ώ
π Read
via "Tech Republic".
Technologies are available to better protect the data used in artificial intelligence, but they're not quite ready for prime time, says Deloitte.π Read
via "Tech Republic".
TechRepublic
Deloitte: How sensitive AI data may become more private and secure in 2022
Technologies are available to better protect the data used in artificial intelligence, but they're not quite ready for prime time, says Deloitte.
βΌ CVE-2021-20853 βΌ
π Read
via "National Vulnerability Database".
ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vectors.π Read
via "National Vulnerability Database".
βΌ CVE-2021-20864 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent unauthenticated attacker to bypass access restriction, and to start the telnet service and execute an arbitrary OS command via unspecified vectors.π Read
via "National Vulnerability Database".
βΌ CVE-2021-20851 βΌ
π Read
via "National Vulnerability Database".
Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator via unspecified vectors.π Read
via "National Vulnerability Database".
βΌ CVE-2021-20854 βΌ
π Read
via "National Vulnerability Database".
ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vectors.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40809 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflows.π Read
via "National Vulnerability Database".
βΌ CVE-2021-20861 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent authenticated attacker to bypass access restriction and to access the management screen of the product via unspecified vectors.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43358 βΌ
π Read
via "National Vulnerability Database".
Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files.π Read
via "National Vulnerability Database".
βΌ CVE-2021-20847 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, 38JP_1_26G, 38JP_1_26J, 38JP_2_03B, and 38JP_2_03C) allows a remote unauthenticated attacker to inject an arbitrary script via WebUI of the device.π Read
via "National Vulnerability Database".
βΌ CVE-2021-20859 βΌ
π Read
via "National Vulnerability Database".
ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent authenticated attacker to execute an arbitrary OS command via unspecified vectors.π Read
via "National Vulnerability Database".